Throwback Thursday: Holding the Bady

Posted by Helen Martin on Jul 21, 2016

Last week saw the 15th anniversary of the appearance of 'Code Red' (also known as 'Bady') - the first fileless worm, which spread by exploiting a vulnerability in Microsoft IIS, even penetrating Microsoft's own IIS servers.

Part of the worm's payload was to launch denial of service attacks against a number of fixed IP addresses - including the then IP address of the White House website.

In August 2001, Costin Raiu analysed the Win32/Bady.worm, concluding that, had the worm been written just a little more carefully, the impact and damage it caused could have been much, much worse.

Costin's article can be read here in HTML-format, or downloaded here as a PDF.

Thousands of websites, including many sites of government organisations in the UK, the US and Sweden, were recently found to have been serving a cryptocurrency miner. More interesting than the incident itself, though, are the lessons that can be…

Users of the popular WordPress content management system are urged to manually update their installation to version 4.9.4, as a bug in the previous version broke the ability to automatically install updates.